VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2025-21054MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.

  • CVE-2025-21053MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

  • CVE-2025-21052MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

  • CVE-2025-21051MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2025-21045MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-21034MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.

  • CVE-2025-21033MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-21029MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.

  • CVE-2025-21026MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.

  • CVE-2023-21471MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.

  • CVE-2023-21470MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.

  • CVE-2023-21469MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.

  • CVE-2025-21015MedAug 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

  • CVE-2025-20990MedAug 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.

  • CVE-2025-21003MedJul 8, 2025
    risk 0.26cvss 4.0epss 0.00

    Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-20993MedJun 4, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2025-20992MedJun 4, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory.

  • CVE-2025-20991MedJun 4, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.

  • CVE-2025-20980MedMay 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

  • CVE-2025-20962MedMay 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.

  • CVE-2025-20960MedMay 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.

  • CVE-2025-20950MedApr 8, 2025
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.

  • CVE-2025-20945MedApr 8, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.

  • CVE-2025-20940MedApr 8, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS.

  • CVE-2025-20923MedMar 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary activity with Galaxy Wearable privilege.

  • CVE-2025-20909MedMar 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-20899MedFeb 4, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control in PushNotification prior to version 13.0.00.15 in Android 12, 14.0.00.7 in Android 13, and 15.1.00.5 in Android 14 allows local attackers to access sensitive information.

  • CVE-2025-20896MedFeb 4, 2025
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to access sensitive information.

  • CVE-2024-49416MedDec 3, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information.

  • CVE-2024-34680MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-34679MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.

  • CVE-2024-34677MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.

  • CVE-2024-34670MedOct 8, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.

  • CVE-2024-34658MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.

  • CVE-2024-34652MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

  • CVE-2024-34650MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

  • CVE-2024-34647MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

  • CVE-2024-34636MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.

  • CVE-2024-34635MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

  • CVE-2024-34634MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

  • CVE-2024-34633MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

  • CVE-2024-34632MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

  • CVE-2024-34618MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.

  • CVE-2024-34617MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.

  • CVE-2024-34613MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch.

  • CVE-2024-34603MedJul 8, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.

  • CVE-2024-34599MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege.

  • CVE-2024-34583MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.

  • CVE-2024-20900MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.

  • CVE-2024-20899MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

Page 38 of 47